Documentation Index
Fetch the complete documentation index at: https://mintlify.com/octra-labs/pvac_hfhe_cpp/llms.txt
Use this file to discover all available pages before exploring further.
Overview
This module provides cryptographic hash functions (SHA-256) and extendable-output functions (SHAKE256) for key derivation, commitments, and deterministic randomness expansion in PVAC-HFHE.SHA-256
Sha256
SHA-256 hash state for incremental hashing.Hash state (eight 32-bit words)
Total number of bytes processed
Input buffer for the current block
Current position in buffer
Methods
init
Initializes the hash state.update
Processes data incrementally.Pointer to data to hash
Number of bytes to process
finish
Finalizes the hash and produces the digest.Output buffer for 256-bit (32-byte) digest
Convenience functions
sha256_bytes
Computes SHA-256 hash of a single buffer.Input data
Input length in bytes
Output digest
sha256_acc_u64
Accumulates a 64-bit integer into the hash in little-endian format.Hash state
Value to hash
SHAKE256
Shake256
SHAKE256 XOF (extendable-output function) state.Keccak state (1600 bits)
Rate parameter (136 bytes for SHAKE256)
Current position in rate bytes
True if in squeezing mode, false if absorbing
Methods
init
Initializes SHAKE256 state.absorb
Absorbs input data into the sponge.Input data
Input length in bytes
pad
Finalizes absorption and switches to squeezing mode.squeeze
Extracts output bytes from the XOF.Output buffer
Number of bytes to extract
You can call
squeeze() multiple times to extract as much output as needed. The function automatically calls pad() if not already in squeezing mode.next_u64
Extracts the next 64-bit integer from the XOF.Next 64 bits of output
XofShake
XofShake
High-level wrapper for SHAKE256 with domain-separated seeding.Methods
init
Initializes XOF with a label and seed.Domain separation label (e.g., from
Dom namespace)Seed values in little-endian format
take_u64
Extracts the next 64-bit value.Next 64-bit value
bounded
Generates a uniformly random integer in the range [0, M).Upper bound (exclusive)
Uniformly random value in [0, M)
This function uses rejection sampling to ensure uniform distribution, avoiding modulo bias.
Utility functions
hex8
Converts binary data to hexadecimal string.Input data
Number of bytes
Hexadecimal string (lowercase)
Usage patterns
Computing public key digest
Deterministic random stream
Sampling without replacement
Commitment scheme
Security properties
SHA-256
- Collision resistance: ~128-bit security
- Preimage resistance: 256-bit security
- Second preimage resistance: 256-bit security
SHAKE256
- Security level: 256-bit (for 512-bit output)
- Collision resistance: 128-bit
- Uniformity: Output is computationally indistinguishable from random
Performance
- SHA-256: ~300-500 MB/s on modern CPUs
- SHAKE256: ~150-250 MB/s on modern CPUs
- Hardware acceleration (AES-NI, SHA extensions) not currently used
Related
- Types - Domain separation constants
- Random generation - Cryptographically secure random bytes
- Field operations - Used with deterministic randomness